logo

CVE-2026-25592: Critical Semantic Kernel Flaw (CVSS 10.0) Allows File Overwrite

ID: b36c552b-b67d-5cc3-b27c-1c5a9c2a6d84

STIX ID: report--b36c552b-b67d-5cc3-b27c-1c5a9c2a6d84

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-02-10

Date Updated: 2026-04-23

Author: Ddos

...
...

Microsoft warned of CVE-2026-25592, a critical (CVSS 10.0) arbitrary file write vulnerability in Semantic Kernel.NET's SessionsPythonPlugin that fails to validate paths for DownloadFileAsync and UploadFileAsync, potentially allowing agents or attackers to overwrite sensitive host files; the issue is fixed in Microsoft.SemanticKernel.Core v1.70.0 and a temporary workaround is to implement a Function Invocation Filter to whitelist allowed localFilePath values.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.